Showing posts with label web check. Show all posts
Showing posts with label web check. Show all posts

Friday, October 09, 2015

, , , , ,

VirusTotal += CloudStat URL scanner

Today we are introducing a new URL scanner that will be characterizing URLs submitted by users to VirusTotal: CloudStat. In their own words:
CloudStat is a new platform set to revolutionize the way companies collect and analyze their data. It identifies compliance gaps, detects configuration problems and warns customers of cyber security threats by applying our proprietary analysis engine to millions of data points. It delivers concise actionable reports directly to mobile devices. The team behind CloudStat is dedicated to helping companies mitigate risks, increase productivity and reduce costs.
Let us look at how their verdicts show up:
https://www.virustotal.com/en/url/2ea21e20088c61bbcec94722c5ef9dd17a663f03869c1f85cacab5c705288064/analysis/
https://www.virustotal.com/en/url/a6ae8a164711f280e4df6d88ba9cd8a7b5acc491824b29e09fdd4e0ff951944c/analysis/
https://www.virustotal.com/en/url/de364f9419c0ed25ed9731e7afb412a0a5d647774c2c54fab2bbee72215519ad/analysis/

Judging by the reports, it seems that this new engine nicely complements other datasets, such that aggregate threat coverage has been improved, this is good news. Hopefully this addition results in more secure users world-wide.

Welcome CloudStat!

Tuesday, November 18, 2014

, , , , ,

virustotal += Blueliv URL scanner

We are excited to announce that we have just integrated Blueliv's malicious URL tracker in virustotal, as yet one more URL scanner providing verdicts on URLs submitted by users. In their own words:
Blueliv is a leading provider of cyber threat information and analysis intelligence for large enterprises, service providers, and security vendors. The company’s deep expertise, data sources, and cloud-based platform address a comprehensive range of cyber threats to turn global threat data into real-time actionable intelligence specifically for each client in an easy-to-use dashboard. Blueliv’s clients include leading bank, insurance, telecom, utility, and retail enterprises.
At present, Blueliv's tracker is highly focused on sites used as C&C infrastructure for trojans, URLs distributing malware and sites with exploit kits, an example of their detections can be found in the following reports:
https://www.virustotal.com/en/url/78b30edc4de035348586cd408626009bbc42be366873e65a8bcc4f35f780f783/analysis/1415884660/
https://www.virustotal.com/en/url/885b6e1dc91e1f01413c0316117f294203d643a1ef3ec79c17556956ff08d086/analysis/1415890213/

Hopefully this integration will lead to increased knowledge about threats and will help protect users world-wide.

Welcome Blueliv!

Friday, October 17, 2014

, , , , , ,

virustotal += Baidu-International URL scanner

And we are in our sixties with respect to the number of URL scanning engines integrated in VirusTotal, welcome Baidu-International! Not so long ago we introduced their file scanner and today we are excited to populate the malicious URL dataset with their verdicts.

In their own words:
Baidu Antivirus is a permanently free and easy-to-use antivirus software which offers proactive defense, file protection, USB protection, download protection, browser protection, and other professional security features. 
As part of the browser protection component they offer they come across and have to research many malicious URLs per day, these URLs will now trigger alerts on VirusTotal. An example of their engine in action can be found below:
https://www.virustotal.com/en/url/000feb4703a2f1b3a84ad435c46da9f523ea9daec84747b12bf8345ef2908de8/analysis/1413373146/

Welcome Baidu-International!

Wednesday, September 24, 2014

, , , , , ,

virustotal += PhishLabs URL scanner

Yet another malicious URL dataset is joining virustotal today. Welcome PhishLabs.

In their own words:
PhishLabs provides cybercrime protection and intelligence services that fight back against online threats and reduce the risk posed by phishing, malware, and other cyber-attacks. They fight back against online threats by detecting, analyzing, and proactively dismantling the systems and illicit services cybercriminals depend on to attack businesses and their customers.

As part of the investigations that they conduct and the Intelligence that they gather, PhishLabs comes across many malicious URLs every day, from now on virustotal checks will also run against their blacklist, enhancing users' ability to detect recent threats.

An example of a report containing an PhishLabs report can be found below:
https://www.virustotal.com/en/url/0ec471bc92bb025a95945ba57004d23cc5854bb8ce686a02f92375cdccffa341/analysis/

Welcome PhishLabs!

Tuesday, July 29, 2014

, , , , , ,

virustotal += OpenPhish URL scanner

We keep increasing the number of engines integrated in virustotal's URL scanning backbone. Today is the turn of OpenPhish. OpenPhish is a service developed by FraudSense, whose engine was integrated a couple of weeks ago, that serves as a free repository of phishing sites detected with FraudSense's Phishing Detection Technology.

In their own words:
OpenPhish is a free service that provides a continuously updated feed of global phishing URLs that were detected by FraudSense's Phishing Detection Technology. The feed includes phishing sites from the past 7 days and is updated in real time with newly detected ones.
The feed is publicly available at:
http://www.openphish.com/

It is also served as plain text at the following URL:
http://www.openphish.com/feed.txt

An example of a report containing an OpenPhish report can be found below:
https://www.virustotal.com/en/url/7f50f5c8baf4671d4f0d54bc6b7d765292bfa9f922b6f382d1723a8d5d3fcb38/analysis/1406625327/

Hopefully this new addition will beef up virustotal's detection capabilities when it comes to phishing sites, which even though is an old scam, it is still very extended and a common threat for the average Internet user.

Welcome OpenPhish!

Wednesday, November 13, 2013

, , , , ,

VirusTotal += malwares.com URL checker

Many security industry actors build solutions that lie in the perimeter of networks, inspecting traffic and discriminating potentially malicious content. One of these solutions is SIMBA from Saint Security (others include FireEye, Fidelis XPS, Damballa, etc.).

In inspecting traffic, these solutions have a privileged position to perform correlations to discover and characterize malicious patterns, this is what allows these companies to discover thousands of malicious URLs and files every day. Saint Security has made part of their discriminatory logic available at malwares.com:
As a cloud-based malicious codes database system, malwares.com is a one-stop service to collect, analyze and detect various malicious codes or malwares such as Trojans, Viruses, Worms so that customers or end-users can make proper security policies to take countermeasures against security threats.
Today we are excited to announce that malwares.com has been integrated in VirusTotal as a URL checker and as of today URL scans will be enriched with their dataset of malicious verdicts. This inclusion is very interesting as it covers much of the threat landscape seen in South Korea, a clear example of this is the following report:
https://www.virustotal.com/en/url/3625ed7252e98152ad781b3deea92038bc1d416c343f8b7bfe2a3ec8ca5b3727/analysis/

Welcome on board and thanks for joining us!

Thursday, October 31, 2013

, , , ,

VirusTotal += AegisLab WebGuard

Our effort to pump up our URL scanner backbone continues, today we are excited to announce the integration of AegisLab WebGuard, a concise malicious URL database to prevent malicious URLs whose characteristics are described by its developers as:
Fast update and leave less open window for attack. Less false positive than other web filter DBs. Website hijacking prevention. Concise malicious URL database. Including: Drive-by-Downloads, BlackHat SEOFake Anti-Virus, Installer and Updates, Scarewares and etc.
You can read more about the kind of threats that AegisLab WebGuard intercepts in this blog post: http://blog.aegislab.com/?p=78

Welcome on board guys, thanks for joining VirusTotal!
, , ,

VirusTotal += RiskAnalytics AutoShun

What is AutoShunAutoShun is a small appliance that protects your network from attacks. Automatically updates itself within minutes to bidirectionally block new threats. One AutoShun device is able to protect an entire site. Configurable whitelist to ensure business partner communications. Ability to block traffic by geographic regions. Reporting on all blocked threats and traffic.
This is the way the RiskAnalytics team describes its AutoShun solution. As you may infer, in order to be able to bidirectionally block threats, AutoShun works (among other technologies and logistics) with a dataset of online threats. From now onward VirusTotal users will also be able to check their submitted URLs against this dataset, which appears in VirusTotal under the name of AutoShun.

Thank you RiskAnalytics!

Wednesday, March 06, 2013

, , , , ,

VirusTotal += Fortinet URL Scanner


FortiGuard Labs analyzes events in real time throughout cyberspace, including both the domain (URL) and IP level. If a website or server hosts malware, attack code, or has been used in spam emails these events will be analyzed by the lab. A history of these events, along with additional intelligence data is available through our URL and IP Lookup tool.
This is how Fortinet describes its web filtering solution which has just been integrated in VirusTotal. With this inclusion we reach 38 URL scanners, we want to surpass 40, hence, if you have any interesting malicious URL dataset or URL scanner please do not hesitate to contact us, we will be more than happy to include you!

This is a permalink to a report showing Fortinet's detection of a phishing site:
https://www.virustotal.com/en/url/3b7819d0ced38ed3d754fcf34378a07c6fc6559116353534ac028d6395020197/analysis/1362562630/

Thank you Fortinet team!

Friday, November 30, 2012

, , , , , , ,

VirusTotal += ADMINUSLabs

Continuing the trend of engine inclusions we have just added ADMINUSLabs as a new URL scanner. In words of ADMINUSLabs itself:
ADMINUSLABS has built an incredibly robust and comprehensive binaries and malware collection and analysis set of tools, enabling organizations of all sizes to leverage the data analyzed and threats monitored to build better defense system. With clients and partners in every continent, ADMINUSLABS solutions offer industry leading technology, flexibility, cost effectiveness, and service levels.
ADMINUSLabs has shared its malicious URL dataset with VirusTotal, from now on, whenever a user submits a URL to VirusTotal for scanning it will also get checked against ADMINUSLabs' dataset and flagged as malicious if present in it. This is an example of a report with one such detection:

https://www.virustotal.com/url/0048c271f6c90bc6959c0eb91ed139692a1ec0f0f4b3328a9ad09baad010c7c2/analysis/1354276484/

ADMINUSLabs' dataset is very large and gets updated several times per day with thousands of new URLs, this is an excellent addition, many thanks and welcome on board!